Clients or security scan tools may raise concerns regarding the following CVEs related to the third-party moment.js library:
CVE-2016-4055
CVE-2017-18214
CVE-2022-24785
CVE-2022-31129
In WCC 12.1.x environments, running strings against the file /opt/CA/WorkloadAutomationAE/wcc/tomcat/webapps/quickview/scripts/moment.min.js reveals that it utilizes version 2.23.0. Per the National Vulnerability Database (NVD), upgrading moment.js to version 2.29.4 or higher is required to clear all version-level vulnerability findings.
As there are no specific standalone security patches addressing this for the 12.1.x release line, users want to know if upgrading to WCC 24.2 (which bundles version 2.30.1) is the only method of remediation.
Workload Control Center (WCC) 12.1.x (e.g., 12.1 SP1 CUM4)
Workload Control Center (WCC) 24.2
A detailed security review of the moment.js library (version 2.23.0) bundled within WCC 12.1.x indicates that the application is not vulnerable to exploitation for any of the four reported CVEs.
CVE-2016-4055 and CVE-2017-18214 — Not Vulnerable These flaws were resolved in older releases of the library. The version deployed with WCC 12.1.x (2.23.0) already includes the necessary upstream fixes for these two vulnerabilities.
CVE-2022-24785 and CVE-2022-31129 — Version Affected, but Not Exploitable Although version 2.23.0 falls within the version window flagged by scanners for these vulnerabilities, they cannot be exploited in WCC. To exploit these CVEs, an attacker must have a vector to pass malicious, untrusted input into specific moment.js functions. Within the WCC QuickView application framework, moment.js is strictly used to render and format the current system time on the display interface—no user input or external parameters are ever passed to it. Consequently, there is no path for an attacker to trigger the vulnerabilities.
Version Context & Remediation Summary:
WCC 12.1.x: Out-of-the-box library version is 2.23.0. The application is entirely secure against these CVEs based on library usage implementation. No individual patch is required or provided for 12.1.x.
WCC 24.2: This release naturally addresses the version-level scan findings by upgrading the bundled library to moment.js version 2.30.1, which satisfies the NVD-recommended 2.29.4+ threshold.
To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on the respective region.